T08 · Insecure Dependencies
- Location
SKILL.md:161- Finding
Unpinned Third-Party Dependencies Installed from a Mutable Package Index
- Content
View full analysis
- Remediation
View remediation
rembg== piexif== exif== ``` 2. Generate and verify cryptographic hashes for every package and transitive dependency. 3. Install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Maintain a lock file generated from a controlled build environment. 5. Document the expected package index and recommend disabling unexpected extra indexes to reduce dependency-confusion exposure. 6. Review dependency updates before changing pinned versions, including transitive dependencies and build-system requirements. 7. Prefer prebuilt, verified wheels where practical and install dependencies in a dedicated, least-privileged virtual environment. ]]>
